> For the complete documentation index, see [llms.txt](https://docs.keystonefi.xyz/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.keystonefi.xyz/reference/whitepaper.md).

# Whitepaper

*Keystone Finance · Whitepaper v2.0 · 21 August 2026 · Kamran Choudhry*

***

## ksUSD turns SOL staking into dollar yield

Deposit USDC. The vault buys staked SOL and shorts the same amount of SOL perp. Price risk cancels down to a small residual, and the staking yield is what is left. You hold a vault share, not a pegged dollar: your balance is fixed, and the share price rises as that yield accrues — and can fall. Nothing is emitted, nothing sits off-chain, and every position is verifiable on Solana.

**One program · one vault · one share mint.**

| Where the yield comes from                                 | Net APY                 | Bear year → bull year | Floor             | Max drawdown                    |
| ---------------------------------------------------------- | ----------------------- | --------------------- | ----------------- | ------------------------------- |
| \~82% of NAV in jitoSOL staking; funding is a small kicker | **5.61%** (6.00% gross) | 4.76% → 6.75%         | \~4% USDC lending | **−0.268%** (24-month backtest) |

**Status: pre-deployment.** v1 hedges on Phoenix Perps (Ellipsis Labs) with USDC margin via the Ember program; jitoSOL is held unlevered as the spot leg. Devnet only, audit pending. Phoenix launched Dec 2025, so the backtest uses historical CEX SOL-perp funding as a proxy.

## I. Where the yield comes from

Almost every yield-bearing dollar on-chain is, underneath, a bet on perp funding. This one isn't.

Funding is the obvious thing to build on, and the first thing to go when you need it. Ethena showed both halves: sUSDe rode positive funding to around 15% through 2025, then settled back to 3.7% as funding compressed.¹ Build a dollar on funding and you inherit funding's cycle. Here, funding is upside on a conversion that already works without it.

Fully hedged, per $100 of NAV per year:

| Leg                                            | Per year   |
| ---------------------------------------------- | ---------- |
| $81.8 of jitoSOL @ 7% staking                  | **+$5.73** |
| $8.2 of USDC margin at Phoenix @ 0%            | $0.00      |
| $8.0 of redemption buffer, lent @ 4%           | +$0.32     |
| $2.0 of buffer held raw for instant redemption | $0.00      |
| Funding on the short                           | \~+$0.24   |
| Perp fees + 2 mode switches                    | −$0.28     |

The staking leg alone earns more than the vault's entire net APY. Funding adds a few tens of basis points at the rate Phoenix actually pays: over the past week its median hourly funding was zero, with 27% of hours positive.

The vault does collect that funding — it just isn't what carries the return. Switch each leg off in the backtest and the asymmetry is total: **with funding off the vault still nets 5.99%; with staking off, funding alone nets −0.08%**, not even covering perp fees and the margin haircut. Staking isn't the larger share. It's the product, and funding is a kicker on a trade that already works.

That says something about Phoenix's age, not about the trade. Funding is the price of leverage on a given venue, paid by whichever side of *its* book is crowded. Phoenix's is young and roughly balanced, so there is no long crowd to collect from. Binance — same asset, mature book — paid \~3.76% over the same window.

**Funding arrives with traders.** If Phoenix's book matures toward what established venues pay, the same position nets 6.28% instead of 5.61% — about 67 bps of upside, on the same growth that lifts the deposit cap. The headline assumes none of it.

Two things follow from that:

* **The correlation profile genuinely differs from both incumbents.** RWA dollars move with the Fed. Ethena moves with the crypto leverage cycle. This moves with Solana network activity.
* **The yield risk that matters is staking-rate compression, not thin funding.** Thin funding barely dents the return, and deeply negative funding parks the vault in USDC lending where it still earns. If Solana's staking rate falls there is nothing to park into; the ceiling simply comes down.

## II. How it works

### Two modes, one rule

| Mode             | Position                                                                     | Earns                              |
| ---------------- | ---------------------------------------------------------------------------- | ---------------------------------- |
| **Normal basis** | long jitoSOL spot (unlevered) + short SOL-PERP on Phoenix at 1×, USDC margin | jitoSOL staking + funding received |
| **Parked**       | all capital in USDC lending (Kamino)                                         | lending yield (\~4–5%)             |

jitoSOL is held outright as the spot leg and USDC is posted as perp margin via Ember: no LST is used as perp collateral. Mode switches cost ≈20–40 bps round-trip. **Reverse basis is not in v1:** harvesting negative funding means borrowing, and the hurdle cleared on only \~2% of days over the 24-month window. Parked covers that range instead, and **v1 never borrows**.

<figure><img src="/files/TS0IbZEvvpJwuglwtmIC" alt="Smoothed perp funding decides the mode: when funding clears the dynamic threshold (−2.6%) the vault moves to Normal basis (short plus staking); when funding is below it the vault moves to Parked (USDC lending). Transitions are automatic, driven by the funding signal."><figcaption><p>One on-chain signal, smoothed funding, decides the mode.</p></figcaption></figure>

### When it switches

The vault stays hedged for as long as hedging beats parking. Compare the two on $100:

|                      | Parked             | Normal basis                              |
| -------------------- | ------------------ | ----------------------------------------- |
| Where the money sits | $90 lent on Kamino | $81.8 in jitoSOL, $8.2 as perp margin     |
| What it earns        | 4% on all of it    | 7% on the $81.8; the margin earns nothing |
| **Per year**         | **$3.60**          | **$5.73**                                 |

Hedging starts **$2.13 ahead**, and that surplus is the budget the short is allowed to burn. The short covers $81.8 of SOL, so $2.13 is **2.6%** of it. Funding can run all the way down to **−2.6%** and the vault is still better off hedged.

That is the whole rule. Not "is funding positive?" but "has the short started costing more than $2.13?" The keeper recalculates that number each cycle from live staking and lending rates, so it moves when they do.

**Why the spread is the product.** The return is not the funding rate. It is the gap between what staking pays and what lending pays. Funding only decides whether the hedge is worth carrying, which is why the threshold sits below zero rather than at it. That same gap names the failure. If lending rises to meet staking, the threshold turns positive, funding at the near-zero rate Phoenix pays cannot clear it, and the vault parks for good — a Kamino deposit carrying the operational risk of a hedged one. Staking-rate compression closes the gap from the other side. Neither side is hedged, which is why the keeper measures both rates every cycle instead of assuming either. A constant on either side would leave half the rule blind to the thing that ends the strategy.

**What the floor is set to.** `init-v1.ts` deploys the on-chain floor at **−260**, the break-even itself, and the keeper can only ever be tighter than the floor, never looser. So the program will short through mildly negative funding, and the keeper's dynamic rule decides when it actually does. At the funding Phoenix pays today that is worth roughly 110 bps against a floor of zero. What it gives up is the guarantee that the program itself can never short into negative funding. The figures here use −260.

The threshold applies as a **±3% hysteresis band** rather than a line. The vault opens only once funding clears the threshold by the band, and holds until funding falls clearly below. At −2.6% funding rarely comes near the line, so the band costs about 6 bps — cheap insurance rather than load-bearing. It is what stops the vault whipsawing if a sustained negative-funding regime ever puts funding back on the threshold.

Transitions run automatically: the smoothed on-chain funding signal decides, a keeper bot executes, and a 7-day mean plus a 12-hour minimum hold filter out the noise. See [Strategy & Modes](/how-it-works/strategy-and-modes.md#when-does-the-vault-turn-the-trade-on).

### Near zero, not zero

Four things stop the legs cancelling exactly. The spot leg is jitoSOL while the short is SOL-PERP, so they offset only while the jitoSOL/SOL ratio holds; a depeg is a straight loss. Delta drifts between rebalances. Staking accrual is left unhedged on purpose, because that appreciation is the yield, so the vault carries a small deliberate net long. And the perp can trade away from spot, with the position marked against the perp.

None of this is large in ordinary conditions. It is still enough that "no price risk" would be the wrong claim. See [Risk](/how-it-works/volatility-risk-management.md).

### What the conversion costs

Every dollar posted as margin is a dollar not earning staking yield. At v1 sizing about **9.1% of deployed capital sits at Phoenix as USDC margin earning nothing**, which is about **8.2% of NAV**, against **81.8% in jitoSOL** earning the staking rate. A further 10% of NAV is the redemption buffer — 8% lent on Kamino, 2% held raw. That allocation is already inside every net figure here: the staking leg contributes 5.73 of the 6.00% gross.

The obvious dismissal is that this is a hedged jitoSOL wrapper. The difference shows up when funding inverts. A naive hedged LST keeps paying to hold its short and bleeds; ksUSD closes and parks in USDC lending. That exit costs 20–40 bps, is written into the program, and runs automatically on a signal nobody has to interpret. Parking is the part that isn't a wrapper.

## III. Why the hedge is the product

The hedge performs the conversion, so anything that can break the hedge breaks the product. That isn't a risk sitting beside the design; it is a hole in it. A venue that halts trading, or auto-deleverages a profitable short to cover someone else's loss, doesn't give ksUSD a bad day. It removes the leg that makes the yield a *dollar* yield, while the vault still holds the jitoSOL.

So the venue choice carries weight rather than being a footnote. Phoenix settles on-chain. The vault opens, defends and closes its own hedge by calling the program directly, the position is visible on Solana, and no operator sits in between. That doesn't remove venue risk — §VII is specific about what remains — but it puts the mechanism somewhere it can be inspected, which is the minimum you should want from the thing the product depends on.

## IV. The share, and what it costs

ksUSD is a **non-rebasing** share token. Your balance stays fixed and the share price rises as carry accrues. Redemption is against NAV, instant from the liquidity buffer and queued for larger size.

It is a share in a hedged carry vault, not a dollar-pegged stablecoin. No fixed yield, no RWA, no emissions, no view on where SOL goes. The architecture is small on purpose: one program, one vault, one rule set.

| Yield source        | Active when               | Contribution          |
| ------------------- | ------------------------- | --------------------- |
| **jitoSOL staking** | Normal basis (spot leg)   | **\~7% APR**          |
| Phoenix funding     | Normal basis              | 0–15% APR (\~0 today) |
| USDC lending        | Buffer + reserve + parked | \~4–5% APR            |

| Fee          | Rate                                   |
| ------------ | -------------------------------------- |
| Management   | **0%**                                 |
| Performance  | **20%, and only above a hurdle**       |
| Reserve skim | **5% of perf** → on-chain reserve fund |
| Withdrawal   | **0%**                                 |

**The floor is a Kamino deposit; the upside is 80% of everything above it.** The hurdle is the USDC lending rate — what the same capital would earn sitting in Kamino by itself — so the performance fee applies only to what the vault adds on top. A year that returns exactly the hurdle costs nothing, so the fee cannot drag a holder under the benchmark. Above it, they keep 80 cents of every dollar of edge.

Parked mode is why this matters. Parked, the vault *is* a Kamino USDC deposit: no perp, no hedge, nothing the holder couldn't do themselves in a single transaction. Taking a fifth of that return would be charging a performance fee for holding a deposit, and it would leave a parked holder behind where they'd have been lending the USDC directly. The hurdle gives those days' yield back in full, so the fee starts only where the strategy does. Across the backtest window it cuts fees charged by 65%, from $2.59 to $0.91 per $100.

The rate isn't fixed in code. `hurdle_apr_bps` is read from Kamino's live supply APY at deploy and maintained against the smoothed rate afterwards. See [Fees](/reference/fees.md).

## V. Why this only assembles on Solana

The design needs four things on one chain, close enough together to compose:

* **An on-chain perp.** The vault opens its hedge by calling into Phoenix Perps with USDC margin from its own program. Phoenix settles on-chain, and that direct call is the part that doesn't port.
* **Funding it receives**, rather than a pool borrow-fee it pays.
* **A high-yield LST and deep USDC lending.** jitoSOL held unlevered as the spot leg; Kamino for the liquidity buffer and parked NAV.
* **Fees low enough** that regular rebalancing stays economic.

On Ethereum these don't line up. Gas makes rebalancing expensive, the deepest perps sit off-chain or on separate domains, and LST yield, funding and lending live apart from each other. The spot leg also earns more here: Solana staking plus MEV tips put jitoSOL near 7% against roughly 3% for Ethereum LSTs. The staking leg is where the return comes from, so that gap matters more than the composability argument does.

## VI. What the backtest shows

Daily resolution, August 2024 to July 2026, spanning the 2025–26 funding compression. The v1 set, normal plus parked, turned $100 into **$111.54** while never giving back more than **0.268%** from a peak. It held the hedge on 98.5% of days and switched modes twice.

| Variant                  | Net APY     | Gross APY | $100 net →  | Max DD                |
| ------------------------ | ----------- | --------- | ----------- | --------------------- |
| **Normal + parked (v1)** | **5.61%**   | 6.00%     | **$111.54** | **−0.268%**           |
| USDC lending benchmark   | \~4%        | —         | —           | flat floor            |
| sUSDe benchmark          | \~5% recent | —         | —           | bleeds in low funding |

**The drawdown is the number worth reading.** Holding a 0.268% peak-to-trough loss through a funding collapse says something about the design.

That 5.61% is fully loaded. The performance fee, the margin-capital haircut where USDC posted as margin earns nothing, and trading costs are all inside it. Against USDC lending it leaves about 161 bps of edge.

### It holds up in the bear, and earns more in the bull

Across every rolling 12-month window since Feb 2022, with nothing tuned per period, net APY ranged **4.76% to 6.75%** and max drawdown never exceeded **−0.268%**. Vary only what Phoenix pays and the answer holds too: 5.77% at 0.05× Binance funding, 5.61% at 0.10×, 5.59% at 0.25×, 5.80% at 0.50×, 6.28% at face value.

The ends of that band sort by regime. The floor, 4.76%, is a year in which SOL fell 78%. The ceiling, 6.75%, is the twelve months to November 2024. Staking sets the floor: jitoSOL pays the same whatever SOL does, and it is the engine in every window. Funding is the variable topping — negative in a bear, where the vault parks rather than pay it, and positive when traders crowd the long side.

So the band is narrow *and* asymmetric. Narrow because staking does the work, tilted upward because funding only ever adds. A funding-based dollar has neither property.

### Method

Staking runs at the live 7.0% network rate. Funding comes from daily Binance SOL-perp scaled to **0.10×**, matching what Phoenix has actually been paying — Phoenix launched Dec 2025 and has too little history of its own. The mode threshold is the true break-even, −2.6%, with a ±3% band. The perp leg is over-margined well inside the venue's 15× limit, so \~9% of NAV sits at zero yield. Costs are 5 bps perp fee and 10 bps slippage per side, 20–40 bps per switch.

The funding scale is the softest input — there is no stored Phoenix series yet — and a single stressed month can run worse than the modelled 0.268%. Detail: [historical-simulation.md](/reference/historical-simulation.md).

## VII. What can go wrong

### How redemption works

Share price is NAV divided by shares, marked from on-chain balances and oracle-priced legs. Keeper attestation is bounded by a per-hour change cap and an oracle sanity band, so it cannot mark NAV past what the chain shows. A 10%-of-NAV buffer covers normal redemptions instantly. Larger ones burn at the locked price and settle against what the unwind actually realizes, through a permissionless crank. A queued payout in stressed markets can therefore come in below marked NAV.

### Risks

**Structural — the ones that can end the conversion**

| Risk                           | Mitigation                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Hedge removed by the venue** | The one that matters most, per §III. A market halt, or auto-deleveraging that force-closes a profitable short to cover another trader's loss, ends the conversion while the vault still holds jitoSOL — leaving it long SOL until it can re-hedge or sell. On-chain settlement means the vault can see and act on this itself, and `emergency_close` can unwind the spot leg once the market is readable, but neither prevents an ADL. Sizing the short at a small fraction of open interest is the main defence, and it is why the deposit cap tracks the venue rather than demand. |
| jitoSOL depeg or slashing      | **Marked at market**, via the Pyth jitoSOL/USD feed — so a liquidity discount hits NAV and the share price immediately, not on sale. A discount of `lst_depeg_bps` against the Jito stake pool's redemption rate auto-pauses and arms `emergency_close`. Slashing is unhedgeable, and neither Jito nor any third party reimburses it.                                                                                                                                                                                                                                                |
| Smart-contract                 | Pre-mainnet audit scheduled; devnet only until then.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |

**Venue & counterparty**

| Risk                  | Mitigation                                                                                                                                                                                                                                                                            |
| --------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Perp-venue dependency | Phoenix is the only hedge venue, so an exploit, outage, or socialized loss hits ksUSD directly. Phoenix is in private beta, and trader onboarding needs an Ellipsis builder-access grant, which is a live external dependency. A second venue is the structural fix and is not in v1. |
| Counterparty          | Phoenix, Ember, Kamino, Jupiter, Jito. No single one holds all NAV, but nothing stands in front of a venue failure either — the reserve fund is not insurance, see below.                                                                                                             |
| Swap router           | Jupiter V6 routes every USDC↔jitoSOL swap. Slippage is bounded on-chain. An outage stalls mode rotation; buffer redemptions stay open.                                                                                                                                                |
| Oracle                | Pyth reads gated by 5-min staleness and 2% confidence; outages past that can still cause loss.                                                                                                                                                                                        |

**Yield**

| Risk                     | Mitigation                                                                                         |
| ------------------------ | -------------------------------------------------------------------------------------------------- |
| Staking-rate compression | The primary yield risk. A lower Solana staking rate lowers the ceiling, and parking does not help. |
| Funding compression      | Secondary. The vault parks and earns \~4%; upside above that isn't guaranteed and is \~0 today.    |

**Operational**

| Risk                    | Mitigation                                                                                                                                                                                                    |
| ----------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Liquidation             | The short is over-margined and the keeper tops margin up actively. Both are needed: the jitoSOL sits in the vault while the margin sits at Phoenix, so the venue cannot see the collateral backing the short. |
| Redemption under stress | Buffer and queue absorb normal flow; an extended liquidity drought lengthens the queue and widens unwind slippage.                                                                                            |
| Regime-transition       | Mode switches cost 20–40 bps and can mistime fast funding flips; the 7-day mean and 12-hour minimum hold trade a little latency for far less whipsaw.                                                         |
| Keeper outage           | Buffer withdrawals stay open; rotation and queue processing pause until cranking resumes. Anyone can crank.                                                                                                   |

### How big are these, in numbers

The risk tables above say what can go wrong. These say how much. Both come from `npm run fund:stress`, against the same window and constants as the headline.

**A jitoSOL discount is the largest unhedged exposure.** The short covers SOL, not jitoSOL, so a discount lands directly on the $81.8 basis leg with nothing offsetting it:

| Discount | NAV impact |                                                  |
| -------- | ---------- | ------------------------------------------------ |
| 0.5%     | −0.41%     |                                                  |
| 1.0%     | −0.82%     |                                                  |
| 2.0%     | −1.64%     | roughly a year of net yield                      |
| 5.0%     | −4.09%     | `settle` auto-pauses, `open_position` hard-fails |
| 10.0%    | −8.18%     |                                                  |
| 20.0%    | −16.36%    |                                                  |

The 5% guard measures against the Jito stake pool's redemption rate rather than against 1.0. That matters: jitoSOL appreciates against SOL as rewards accrue, so a guard anchored at 1.0 would drift out of reach and fire on nothing. Slashing sits underneath all of it and is unhedgeable — Jito runs no insurance fund and nobody reimburses it.

**What the reserve fund is, and what it is not.** It is not depeg cover and it is not insurance. A reserve standing in front of market risk would have to be sized against it, and the arithmetic doesn't work: the 5% skim on performance fees accrues on the order of two basis points of NAV a year, against a 1% discount that costs 0.82%. No skim rate closes that gap — taking every performance fee wouldn't.

That's the right outcome rather than a gap to fill, because **ksUSD defends no peg**. An insurance fund is what a pegged dollar needs, since a discount there is an existential failure. Here the share price absorbs the shock: NAV is marked at market, the price is designed to be able to fall, and a holder exiting into a bad unwind bears it rather than passing it to the holders who stayed. Reserving against market risk would contradict all of that.

What the reserve *is* for is narrower and real: shortfalls the protocol caused rather than the market — a bad fill, an oracle mismark later corrected, an accounting gap. Holders did not sign up for those, so making them whole is right. The category is also small and bounded, which is why a small reserve is the right size for it.

**How often the short's margin comes under pressure.** The short is the leg that liquidates, so the adverse direction is SOL *up*. Counting intraday highs against the previous close:

| Adverse move | Days | Share |                                                                    |
| ------------ | ---- | ----- | ------------------------------------------------------------------ |
| ≥ 3%         | 289  | 39.6% |                                                                    |
| ≥ 5%         | 139  | 19.0% | about half the entry margin; where a maintenance requirement bites |
| ≥ 9%         | 27   | 3.7%  | exhausts the entry margin outright                                 |
| ≥ 15%        | 4    | 0.5%  |                                                                    |

Entry margin is 9.1% of deployed capital, so a 5% move does not liquidate the position outright. It removes roughly half the cushion, and `add_margin` exists to replace it. The 5% row is often quoted as a liquidation count. It isn't one.

**A realistic bad month.** The modelled worst month is −0.04%, funding only. Adding a depeg and a round-trip reprice on the basis leg gives −1.6% at a 1% discount and −4.9% at 5%. A bad month is dominated by depeg rather than by funding.

### Failure modes

Fallbacks are built in. Funding compression parks the vault. Perp-venue trouble triggers an oracle-divergence auto-pause and a permissionless `emergency_close`. A depeg auto-pauses. Wind-down turns the vault into a pro-rata USDC claim. Redemption works whether or not the team is present.

## VIII. Position

|                | Yield source                                                   | Behaviour when funding dies                                             | Transparency             | Venues                                           |
| -------------- | -------------------------------------------------------------- | ----------------------------------------------------------------------- | ------------------------ | ------------------------------------------------ |
| **ksUSD**      | **Staking**, plus funding and lending                          | Parks at the lending floor                                              | Fully on-chain           | Phoenix, Kamino, Jito (Solana-native)            |
| Hylo (hyUSD)   | LST staking across the whole collateral pool, financed by xSOL | Unaffected by funding; tracks leveraged-SOL demand and rebalancing cost | On-chain                 | LST issuers + its own xSOL tranche and Earn Pool |
| Ethena (sUSDe) | Delta-hedged perp funding                                      | Yield follows funding down                                              | Off-chain CEX, attested  | CEXs + custodians                                |
| MakerDAO / Sky | Stability fees + RWA/savings                                   | Unaffected; tracks rates instead                                        | On-chain + off-chain RWA | RWA counterparties                               |
| Perena (USD\*) | Swap fees + stable yields                                      | Tracks volume instead                                                   | On-chain                 | Solana AMM/DEX                                   |

**Hylo (hyUSD) is the closest Solana-native design, and it out-yields this one today.** It overcollateralises hyUSD with a basket of LSTs and issues xSOL, a junior tranche that absorbs SOL's volatility so hyUSD can hold its peg. Its savings token then earns on the whole pool, because xSOL and unstaked holders forgo their share. As of July 2026 that token pays **≈9.7%**, against 5.61% net here.

**The compression already happened, and it happened the way this section predicted.** The rate is a participation ratio, not a spread — roughly the LST yield times pool value over staked supply — so it is highest when fewest holders are staked, and converges toward the collateral ratio times the LST yield as the product succeeds. Hylo targets a 150% collateral ratio inside a 135–165% band, and LSTs pay about 7%, which puts that convergence at 9.5–10.5%. Q1 2026 printed **52.4%**; the quarter after, the observed rate sits at **9.7%**, inside the predicted band. The 52.4% was not a yield in any durable sense: the stability pool had converted savings backing into xSOL during the drawdown, and the print is xSOL recovering off its lows — a leveraged-SOL result wearing a savings-rate label. Protocol TVL fell from $52M to $22.8M over the same quarter.

Both designs are claims on the same engine. Solana staking pays both. Hylo levers it through its tranche; this vault hedges it with a perp. The lasting difference is the leverage multiple, not the source of the return.

**Hylo's V2 makes its savings token delta-neutral, and the way it does so is the whole argument.** In July 2026 sHYUSD became eHYUSD, marketed as fully delta-neutral. There is no external hedge: Hylo's own documentation describes no perpetual or off-chain derivative position. Neutrality is reached by selling collateral into USDC when the ratio falls, and *"every rebalance settles its profit or subsidy against the Earn Pool by minting or burning hyUSD"* — so *"subsidized rebalances under stress draw it down, the cost of de-risking the system."*

That is the same risk in a new place. Where the old design left the saver exposed once the tranche thinned, the new one charges the saver the cost of de-risking as it happens, in exactly the drawdowns the savings token exists to sit out. The spread schedule is fixed rather than a function of live market data, so the subsidy is not repriced when a fast market makes de-risking expensive. This vault moves the same risk to the perp market, which can halt in the same drawdown — but a hedge counterparty can be replaced, and an internal rebalance charged to your own principal cannot, because it *is* the design. Hylo has no cash state either, where this vault parks in USDC lending.

> **Once coverage falls past 100%, the tranche is gone and hyUSD carries SOL's volatility directly.** The holder who bought a dollar is left holding the exposure they bought it to avoid. That is a different instrument, not a bad quarter. This design can be hurt too, but the damage lands on the share price, marked at market: it degrades, it does not turn into something the holder never bought.

Ethena showed there is real demand for a yield-bearing dollar, and showed what happens when the one source of that yield compresses. The answer here isn't a better funding trade. It is a different engine, with funding as upside rather than foundation.

The longer goal is dollar yield that comes from the market it lives on, and can be checked against it.

*Simulated performance does not predict future results.*

¹ *Ethena figures are directional, per public dashboards from the backtest era.*

***

[app.keystonefi.xyz](https://app.keystonefi.xyz) · [docs.keystonefi.xyz](https://docs.keystonefi.xyz) · *Simulated figures only. Not investment advice.*
